yes i do… still being diverted to unknown sites.
Ran ATF Cleaner and Combo Fix, here is the ComboFix log:
ComboFix 09-12-27.04 - XXXX XXXXXXX 12/28/2009 14:33:48.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1622 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Adobe\sp.DLL
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
H:\Autorun.inf
—– BITS: Possible infected sites —–
hxxp://armmf.adobe com
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-28 )))))))))))))))))))))))))))))))
.
2009-12-28 18:41 . 2009-12-28 18:41 ——– d—–w- c:\program files\ESET
2009-12-23 02:44 . 2009-12-23 02:44 ——– d—–w- c:\program files\Trend Micro
2009-12-23 02:38 . 2009-12-23 02:38 ——– d—–w- c:\program files\TrendMicro
2009-12-10 03:46 . 2009-12-28 17:51 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-10 03:46 . 2009-12-28 17:50 ——– d—–w- c:\program files\Spyware Doctor
2009-12-09 22:05 . 2009-12-09 22:05 ——– d—–w- c:\documents and settings\Elia Sanchez\Local Settings\Application Data\Threat Expert
2009-12-09 18:05 . 2009-12-09 18:05 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
2009-12-09 14:30 . 2009-12-09 14:30 ——– d—–w- c:\program files\Common Files\xing shared
2009-12-09 13:40 . 2009-12-10 02:11 ——– dc—-w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-09 13:40 . 2009-12-09 13:40 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\PC Tools
2009-12-09 13:18 . 2009-12-09 20:15 ——– dc—-w- c:\documents and settings\All Users\Application Data\Google Updater
2009-12-09 05:14 . 2009-12-09 05:14 ——– dc—-w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware com
2009-12-09 05:13 . 2009-12-09 20:11 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\SUPERAntiSpyware com
2009-12-09 05:13 . 2009-12-09 20:11 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-08 19:37 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
2009-12-07 03:43 . 2009-12-07 03:43 ——– dc—-w- C:\$AVG
2009-12-07 03:42 . 2009-12-07 03:42 ——– d—–w- c:\program files\AVG
2009-12-07 03:42 . 2009-12-09 18:30 ——– dc—-w- c:\documents and settings\All Users\Application Data\avg9
2009-12-07 03:42 . 2009-12-07 17:23 ——– d—–w- c:\windows\SxsCaPendDel
2009-12-06 17:52 . 2009-12-06 17:52 ——– d—–w- c:\program files\2Convert net
2009-12-05 22:13 . 2009-12-05 22:13 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\AnvSoft
2009-12-05 18:44 . 2009-12-05 18:44 ——– d—–w- c:\documents and settings\Elia Sanchez\Local Settings\Application Data\Downloaded Installations
2009-12-05 05:19 . 2009-12-05 05:19 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\STOIK
2009-12-02 23:16 . 2009-12-02 23:16 ——– dc-h–w- c:\documents and settings\All Users\Application Data\CanonIJEGV
2009-12-02 23:14 . 2009-12-02 23:14 ——– dc-h–w- c:\documents and settings\All Users\Application Data\CanonIJScan
2009-12-02 23:14 . 2009-12-02 23:18 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\Canon
2009-12-02 23:06 . 2009-12-02 23:06 ——– d—–w- c:\program files\ArcSoft
2009-12-02 23:06 . 1995-08-01 09:44 212480 —-a-w- c:\windows\PCDLIB32.DLL
2009-12-02 23:05 . 2009-12-02 23:05 ——– d—–w- c:\program files\Common Files\CANON
2009-12-02 23:03 . 2009-12-02 23:03 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2009-12-02 23:03 . 2008-04-18 13:51 598016 —-a-w- c:\windows\system32\CNQ4807L.DLL
2009-12-02 23:03 . 2008-04-07 14:58 1339392 —-a-w- c:\windows\system32\CNQ4807C.DLL
2009-12-02 23:03 . 2008-04-07 14:58 98304 —-a-w- c:\windows\system32\CNQ4807I.DLL
2009-12-02 23:03 . 2007-03-15 14:12 188416 —-a-w- c:\windows\system32\CNQ4807O.DLL
2009-12-02 23:03 . 2009-12-02 23:03 ——– d–h–w- c:\program files\CanonBJ
2009-12-02 23:02 . 2009-12-02 23:06 ——– d—–w- c:\program files\Canon
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-28 17:51 . 2007-11-19 22:23 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\uTorrent
2009-12-28 17:50 . 2008-06-26 02:09 ——– dc–a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-27 19:21 . 2009-04-10 10:56 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-27 18:50 . 2009-09-19 22:46 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\vlc
2009-12-21 18:03 . 2002-08-29 07:27 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-12-20 02:03 . 2005-10-29 12:28 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-09 14:31 . 2003-12-16 03:31 ——– d—–w- c:\program files\Common Files\Real
2009-12-09 14:29 . 2003-08-05 18:55 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-12-09 14:29 . 2003-08-05 18:55 348160 —-a-w- c:\windows\system32\msvcr71.dll
2009-12-09 14:29 . 2003-12-16 03:31 ——– d—–w- c:\program files\Real
2009-12-09 13:17 . 2006-05-13 23:54 ——– d—–w- c:\program files\Google
2009-12-05 23:42 . 2009-07-19 02:54 ——– d—–w- c:\program files\Aimersoft
2009-12-05 05:24 . 2003-12-16 03:27 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-11-24 21:04 . 2009-11-24 21:04 ——– d—–w- c:\program files\MSXML 4.0
2009-11-21 15:51 . 2002-08-29 11:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-20 05:01 . 2008-02-03 05:12 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\Orbit
2009-11-20 04:59 . 2009-09-26 11:52 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\dvdcss
2009-11-19 02:33 . 2009-11-19 01:55 2695 —-a-w- c:\windows\checkip.dat
2009-11-19 01:20 . 2009-11-19 01:20 ——– d—–w- c:\program files\Linksys
2009-11-10 09:08 . 2006-06-03 19:54 ——– d—–w- c:\documents and settings\Elia Sanchez\Application Data\Apple Computer
2009-11-02 03:49 . 2009-04-09 16:48 ——– d—–w- c:\program files\iTunes
2009-11-02 03:47 . 2006-06-03 19:46 ——– d—–w- c:\program files\iPod
2009-11-02 03:47 . 2007-12-08 02:35 ——– d—–w- c:\program files\Common Files\Apple
2009-11-02 02:52 . 2009-11-02 02:52 79144 -c–a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-29 07:45 . 2005-06-18 04:49 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2002-08-29 11:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2002-08-29 11:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2002-08-29 11:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-09 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-22 126976]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-25 196608]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-09 198160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= c:\documents and settings\Elia Sanchez\My Documents\My Pictures\Haido\hello.JPG
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.sys
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-06-22 04:48 155648 —-a-w- c:\windows\SYSTEM32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-09 02:17 52256 —-a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-03-15 01:01 71216 ——w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\GridService\\peer.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\KeyHoleTV\\KeyHoleTV.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R1 ehdrv;ehdrv;c:\windows\SYSTEM32\DRIVERS\ehdrv.sys [2/6/2009 11:56 AM 106208]
R1 epfwtdir;epfwtdir;c:\windows\SYSTEM32\DRIVERS\epfwtdir.sys [2/6/2009 11:58 AM 93336]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2/6/2009 11:57 AM 727720]
R3 INIDVD;Initio USB DVD Filter Driver;c:\windows\SYSTEM32\DRIVERS\inidvd.sys [4/24/2009 6:31 PM 7936]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys –> c:\windows\system32\Drivers\avgldx86.sys [?]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys –> c:\windows\system32\Drivers\avgtdix.sys [?]
S2 avg9emc;AVG Free E-mail Scanner;"c:\program files\AVG\AVG9\avgemc.exe" –> c:\program files\AVG\AVG9\avgemc.exe [?]
S2 avg9wd;AVG Free WatchDog;"c:\program files\AVG\AVG9\avgwdsvc.exe" –> c:\program files\AVG\AVG9\avgwdsvc.exe [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?]
S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\SYSTEM32\DRIVERS\WUSB54GCv3.sys [11/18/2009 8:08 PM 627072]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\SYSTEM32\advpack.dll
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
Trusted Zone: internet
Trusted Zone: mcafee com
TCP: {038BBBA4-2129-40DB-B339-796A222DB2C7} = 71.243.0.12 71.250.0.12
FF - ProfilePath - c:\documents and settings\Elia Sanchez\Application Data\Mozilla\Firefox\Profiles\3q7si265.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.searchcanvas com/web?ot=7&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo com
FF - prefs.js: keyword.URL - hxxp://www.searchcanvas com/web?ot=8&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1739.5352\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
MSConfigStartUp-AntiSpyCheck 2 - c:\program files\AntiSpyCheck 2.1\AntiSpyCheck 2.1.exe
MSConfigStartUp-Calendarscope - c:\program files\Calendarscope\cs.exe
MSConfigStartUp-InCD - c:\program files\Nero\Nero 7\InCD\InCD.exe
MSConfigStartUp-NBKeyScan - c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe
MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
MSConfigStartUp-SecurDisc - c:\program files\Nero\Nero 7\InCD\NBHGui.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
MSConfigStartUp-WinAble - c:\program files\WinAble\winable.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer net
Rootkit scan 2009-12-28 14:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8AA86618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf763bf28
\Driver\ACPI -> ACPI.sys @ 0xf75aecb8
\Driver\atapi -> atapi.sys @ 0xf74a0852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: Broadcom 440x 10/100 Integrated Controller -> SendCompleteHandler -> NDIS.sys @ 0xf7439bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7446a21
SendHandler -> NDIS.sys @ 0xf742487b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\INIDVD]
"ImagePath"=multi:"system32\DRIVERS\inidvd.sys\00"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\INIDVD]
"ImagePath"=multi:"system32\DRIVERS\inidvd.sys\00"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(872)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3272)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\BCMSMMSG.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-12-28 15:15:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-28 20:15
ComboFix2.txt 2009-05-07 20:32
Pre-Run: 13,690,019,840 bytes free
Post-Run: 13,613,780,992 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - B101F238FBD050BF22C6F7D66EFE1DDB
here's the latest hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:36:22 PM, on 12/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft0000/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft0000/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft0000/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://*.mcafee0000
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - Unknown owner - C:\Program Files\AVG\AVG9\avgemc.exe (file missing)
O23 - Service: AVG Free WatchDog (avg9wd) - Unknown owner - C:\Program Files\AVG\AVG9\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O24 - Desktop Component 0: (no name) - C:\Documents and Settings\Elia Sanchez\My Documents\My Pictures\Haido\hello.JPG
–
End of file - 5862 bytes
the last ESET NOD32 Antivirus 4 scan stated that: C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Adobe\sp.DLL.vir - a variant of Win32/Agent.QNT trojan - cleaned by deleting - quarantined [1]
thought that was the problem, and tried doing a google search and again was sent to another unknown site.
thanks…
here's the complete ESET scan log:
Scan Log
Version of virus signature database: 4723 (20091228)
Date: 12/28/2009 Time: 5:54:55 PM
Scanned disks, folders and files: Operating memory;C:\Boot sector;C:\
C:\hiberfil.sys - error opening [4]
C:\pagefile.sys - error opening [4]
C:\DELL\BB\BUSINESS\BBBUS.MHT » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Administrator\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript1.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Administrator\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript2.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Administrator\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript3.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Administrator\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript4.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Administrator\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript5.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Administrator\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript6.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Administrator\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript7.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Administrator\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript8.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Administrator\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript9.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » CmnIds.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » images/arrow_right.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » images/btn_signup_52x20.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » images/more_info.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » images/sidetable_bottom.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » images/sidetable_bottom_red.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » images/sidetable_top.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » images/sidetable_top_red.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » images/transpix.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » images/watermark_mys_150x130.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » oemcfg.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » OEMIds.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » valert.htm - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » valert_old.htm - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui » ZIP » hs~valert.htm - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » agentins.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » agntcons.vbs - incorrect CRC checksum, the file may be damaged
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » agntinst.htm - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » agntinst.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » agntlang.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » default.htm - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » header.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » HtmlUtil.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » images/bg_left_1x314.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » images/bg_left_MSC_165x314.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » images/icon_info_16x16.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » images/icon_mcafee_61x61.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » images/icon_progress_checked_13x13.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » images/icon_progress_hot_13x13.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » images/icon_progress_unchecked_13x13.gif - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » InstUtil.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » instwiz.css - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » instxp.css - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » mcccom.lpk - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » pbar.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » setcss.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\MPS_INSTALL_AgentCabs\agentins.cab » CAB » agentins.ui » ZIP » SubInfoData.vbs - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AntiSpyCheck.zip » ZIP » sbRecovery.reg - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AntiSpyCheck.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClickspringOuterinfo.zip » ZIP » sbRecovery.reg - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClickspringOuterinfo.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DeepDive.zip » ZIP » sbRecovery.reg - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DeepDive.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DeepDive1.zip » ZIP » sbRecovery.reg - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DeepDive1.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DeepDive2.zip » ZIP » sbRecovery.reg - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DeepDive2.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(1-11-2005) Time(19-17-5).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(1-11-2005) Time(19-33-59).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(1-11-2005) Time(21-28-37).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(1-12-2005) Time(17-53-8).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(1-2-2006) Time(17-18-7).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(1-4-2006) Time(18-43-57).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(10-3-2007) Time(9-7-26).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(11-5-2006) Time(17-56-7).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(12-1-2006) Time(17-58-36).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(12-4-2006) Time(18-38-48).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(13-4-2006) Time(17-14-24).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(14-6-2006) Time(8-14-4).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(15-11-2005) Time(18-23-54).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(15-6-2006) Time(17-58-50).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(16-9-2006) Time(16-16-48).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(17-3-2006) Time(17-50-33).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(17-3-2006) Time(17-55-40).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(18-10-2006) Time(8-34-8).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(2-10-2006) Time(14-21-13).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(2-11-2006) Time(16-27-39).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(2-2-2007) Time(10-12-42).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(2-2-2007) Time(10-2-30).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(2-3-2006) Time(19-9-49).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(20-12-2005) Time(18-25-5).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(20-4-2006) Time(18-49-31).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(20-7-2006) Time(8-0-28).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(21-3-2006) Time(19-51-14).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(22-10-2007) Time(17-3-21).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(22-5-2006) Time(21-24-29).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(22-6-2006) Time(18-18-12).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(23-12-2006) Time(17-52-0).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(23-3-2006) Time(17-44-6).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(24-10-2005) Time(21-43-12).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(24-10-2005) Time(21-53-51).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(25-10-2005) Time(18-3-2).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(25-2-2006) Time(9-48-48).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(25-5-2006) Time(17-55-6).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(26-10-2006) Time(17-55-1).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(26-12-2005) Time(14-57-9).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(26-2-2007) Time(10-38-31).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(27-11-2005) Time(20-18-10).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(27-4-2006) Time(18-59-2).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(28-12-2006) Time(19-16-55).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(29-10-2005) Time(8-48-25).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(3-11-2005) Time(17-53-44).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(3-8-2006) Time(18-56-11).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(30-11-2005) Time(18-31-35).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(30-12-2005) Time(19-29-10).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(30-7-2006) Time(13-56-52).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(31-3-2006) Time(18-45-55).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(31-3-2006) Time(19-54-46).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(4-2-2006) Time(19-31-18).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(4-4-2006) Time(17-58-56).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(5-1-2006) Time(17-50-11).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(5-11-2005) Time(9-38-2).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(5-3-2006) Time(17-5-16).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(5-5-2006) Time(21-2-28).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(5-7-2006) Time(21-41-17).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(6-1-2007) Time(14-48-51).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(6-4-2006) Time(17-49-49).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(8-2-2007) Time(19-20-17).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(8-4-2007) Time(1-4-9).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(9-2-2006) Time(18-23-26).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(9-3-2006) Time(17-48-40).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » logs/Date(9-5-2006) Time(18-32-32).txt - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » noadware4_111907.na - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/1,12,2006_17,58,32.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/1,5,2006_17,50,6.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/1,6,2007_14,48,47.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/10,18,2006_8,34,4.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/10,2,2006_14,21,2.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/10,22,2007_17,2,56.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/10,24,2005_21,42,42.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/10,24,2005_21,53,48.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/10,25,2005_18,3,0.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/10,26,2006_17,54,55.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/10,29,2005_8,48,21.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/11,1,2005_19,17,2.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/11,1,2005_19,33,57.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/11,1,2005_21,28,36.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/11,15,2005_18,23,51.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/11,2,2006_16,27,32.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/11,27,2005_20,18,8.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/11,3,2005_17,53,32.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/11,30,2005_18,31,32.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/11,5,2005_9,37,57.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/12,1,2005_17,53,6.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/12,20,2005_18,24,49.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/12,23,2006_17,51,57.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/12,26,2005_14,57,2.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/12,28,2006_19,16,51.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/12,30,2005_19,29,5.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/2,1,2006_17,18,4.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/2,2,2007_10,12,33.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/2,2,2007_10,2,21.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/2,25,2006_9,48,45.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/2,26,2007_10,38,21.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/2,4,2006_19,31,5.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/2,8,2007_19,20,5.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/2,9,2006_18,23,22.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,10,2007_9,7,18.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,17,2006_17,50,30.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,17,2006_17,55,28.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,2,2006_19,9,47.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,21,2006_19,51,11.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,23,2006_17,44,4.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,31,2006_18,45,48.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,31,2006_19,54,44.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,5,2006_17,5,11.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/3,9,2006_17,48,32.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/4,1,2006_18,43,55.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/4,12,2006_18,38,44.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/4,13,2006_17,14,21.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/4,20,2006_18,49,29.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/4,27,2006_18,58,54.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/4,4,2006_17,58,54.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/4,6,2006_17,49,46.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/4,8,2007_1,4,5.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/5,11,2006_17,56,4.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/5,22,2006_21,24,25.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/5,25,2006_17,55,5.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/5,5,2006_21,2,27.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/5,9,2006_18,32,29.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/6,14,2006_8,14,1.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/6,15,2006_17,58,47.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/6,22,2006_18,18,6.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/7,20,2006_8,0,19.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/7,30,2006_13,56,50.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/7,5,2006_21,41,14.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/8,3,2006_18,56,6.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » NoAdwareBackup/9,16,2006_16,16,41.zip - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NoAdware.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpyLockedFakeAlert.zip » ZIP » sbRecovery.reg - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpyLockedFakeAlert.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRenos.zip » ZIP » zfe1.exe - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRenos.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRenos1.zip » ZIP » ibmsmyi.dll - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRenos1.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRenos2.zip » ZIP » ibmsmyi.dll - error - password-protected file
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRenos2.zip » ZIP » sbRecovery.ini - error - password-protected file
C:\Documents and Settings\Default User\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript1.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Default User\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript2.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Default User\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript3.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Default User\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript4.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Default User\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript5.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Default User\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript6.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Default User\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript7.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Default User\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript8.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Default User\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript9.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Application Data\Mozilla\Firefox\Profiles\3q7si265.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Downloaded Installations\{95B63520-726E-41D4-AD92-8A4BD82FC62D}\Movavi Video Converter 9.msi » MSI » Data1.cab » CAB » starburn_videocd.iso » ISO » AVSEQ01.DAT - archive damaged
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Downloaded Installations\{95B63520-726E-41D4-AD92-8A4BD82FC62D}\Movavi Video Converter 9.msi » MSI » Data1.cab » CAB » starburn_supervideocd.iso » ISO » AVSEQ01.MPG - archive damaged
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\CRAIGSLIST.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\Drafts.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\HSBC Savings & Credit Card.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\Important + Passwords.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\Inbox.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\Japanese.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\KEEPERS.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\Passwords.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\Publishers Clearing House.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\Receipts.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\Sent Items.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\Takeshi.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\Local Settings\Application Data\Identities\{2C7A8CD0-78FA-427F-BF86-AE333A20DC52}\Microsoft\Outlook Express\teac (1).dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\My Documents\downloads\mbam-setup.exe » INNO » files.info - file is not an archive
C:\Documents and Settings\Elia Sanchez\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript1.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript2.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript3.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript4.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript5.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript6.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript7.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript8.PspScript » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Elia Sanchez\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript9.PspScript » MIME - is OK (internal scanning not performed)
C:\DRIVERS\R106456\Lang\esp\license.txt » MIME - is OK (internal scanning not performed)
C:\DRIVERS\R106456\Lang\ita\license.txt » MIME - is OK (internal scanning not performed)
C:\DRIVERS\R106456\Lang\ptb\license.txt » MIME - is OK (internal scanning not performed)
C:\I386\BoundScript1.PspScript » MIME - is OK (internal scanning not performed)
C:\I386\BoundScript2.PspScript » MIME - is OK (internal scanning not performed)
C:\I386\BoundScript3.PspScript » MIME - is OK (internal scanning not performed)
C:\I386\BoundScript4.PspScript » MIME - is OK (internal scanning not performed)
C:\I386\BoundScript5.PspScript » MIME - is OK (internal scanning not performed)
C:\I386\BoundScript6.PspScript » MIME - is OK (internal scanning not performed)
C:\I386\BoundScript7.PspScript » MIME - is OK (internal scanning not performed)
C:\I386\BoundScript8.PspScript » MIME - is OK (internal scanning not performed)
C:\I386\BoundScript9.PspScript » MIME - is OK (internal scanning not performed)
C:\I386\COMPDATA\MSMQCOMP.TXT » MIME - is OK (internal scanning not performed)
C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\YS561405.CAB » CAB » VIDEO.MHT_1033 » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/deploy/ffjcext.zip » ZIP » {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}/chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/resources.jar » ZIP » com/sun/org/apache/xerces/internal/impl/msg/XIncludeMessages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/resources.jar » ZIP » com/sun/xml/internal/fastinfoset/resources/ResourceBundle.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/resources.jar » ZIP » javax/xml/bind/Messages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_03\lib\resources.jar » ZIP » com/sun/org/apache/xerces/internal/impl/msg/XIncludeMessages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_03\lib\resources.jar » ZIP » com/sun/xml/internal/fastinfoset/resources/ResourceBundle.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_03\lib\resources.jar » ZIP » javax/xml/bind/Messages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_03\lib\deploy\ffjcext.zip » ZIP » {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}/chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_05\lib\resources.jar » ZIP » com/sun/org/apache/xerces/internal/impl/msg/XIncludeMessages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_05\lib\resources.jar » ZIP » com/sun/xml/internal/fastinfoset/resources/ResourceBundle.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_05\lib\resources.jar » ZIP » javax/xml/bind/Messages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_05\lib\deploy\ffjcext.zip » ZIP » {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}/chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_07\lib\resources.jar » ZIP » com/sun/org/apache/xerces/internal/impl/msg/XIncludeMessages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_07\lib\resources.jar » ZIP » com/sun/xml/internal/fastinfoset/resources/ResourceBundle.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_07\lib\resources.jar » ZIP » javax/xml/bind/Messages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre1.6.0_07\lib\deploy\ffjcext.zip » ZIP » {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}/chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre6\lib\resources.jar » ZIP » com/sun/org/apache/xerces/internal/impl/msg/XIncludeMessages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre6\lib\resources.jar » ZIP » com/sun/xml/internal/fastinfoset/resources/ResourceBundle.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre6\lib\resources.jar » ZIP » javax/xml/bind/Messages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre6\lib\deploy\ffjcext.zip » ZIP » {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}/chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Java\jre6\lib\deploy\jqs\ff\chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\chrome\comm.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\chrome\pippki.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\chrome\toolkit.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}\chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Real\RealPlayer\browserrecord\firefox\ext\chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Adobe\sp.DLL.vir - a variant of Win32/Agent.QNT trojan - cleaned by deleting - quarantined [1]
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript1.PspScript » MIME - is OK (internal scanning not performed)
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript2.PspScript » MIME - is OK (internal scanning not performed)
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript3.PspScript » MIME - is OK (internal scanning not performed)
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript4.PspScript » MIME - is OK (internal scanning not performed)
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript5.PspScript » MIME - is OK (internal scanning not performed)
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript6.PspScript » MIME - is OK (internal scanning not performed)
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript7.PspScript » MIME - is OK (internal scanning not performed)
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript8.PspScript » MIME - is OK (internal scanning not performed)
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript9.PspScript » MIME - is OK (internal scanning not performed)
Number of scanned objects: 357458
Number of threats found: 1
Number of cleaned objects: 1
Time of completion: 7:14:23 PM Total scanning time: 4768 sec (01:19:28)
Notes:
[1] Object has been deleted as it only contained the virus body.
[4] Object cannot be opened. It may be in use by another application or operating system.